Ransomware continues to extract payments from roughly half of all victim organizations, even as ransom demands climb and a growing number of governments consider or enact laws that would make paying attackers illegal. The tension between operational survival and emerging legal prohibition is sharpening for healthcare organizations, which remain among the most frequently targeted sectors and face the added pressure of disrupted patient care every hour systems are offline.

The payment calculus

Research published in 2025 by cybersecurity group Sophos found that approximately 47 percent of ransomware victims ultimately pay the demanded ransom. The median demand has been rising year over year, meaning organizations that do pay are writing larger checks than their predecessors — with no guarantee that decryption keys will work or that stolen data will not surface anyway.

For healthcare operators, the calculation carries dimensions that other industries do not face at the same intensity. Clinical systems — electronic health records, imaging platforms, pharmacy dispensing, laboratory interfaces — are not discretionary infrastructure. Downtime translates directly to care delays, patient diversions, and in documented cases, adverse outcomes. That dependency has historically made healthcare a preferred target precisely because the pressure to restore operations quickly is acute.

Where payment bans stand

The UK has signaled intent to restrict ransomware payments, and several other jurisdictions are studying similar measures. The underlying logic is straightforward: as long as payments remain legal and economically rational for victims, the ransomware business model is self-sustaining. Banning payments, proponents argue, collapses the revenue stream that funds criminal infrastructure.

The practical effect on healthcare would be significant. An outright ban would remove payment as a recovery option even when encrypted backups are unavailable or restoration timelines stretch into weeks. That shift would require organizations to treat incident preparedness — tested offline backups, documented manual workflows, rehearsed downtime procedures — not as contingency planning but as the primary recovery strategy. US policymakers have not enacted a federal ban, but HHS has historically discouraged payments, and any move by Congress or the Treasury Department's Office of Foreign Assets Control to tighten restrictions would hit healthcare operators quickly given the sector's exposure.

What the trend means for incident planning

The rising demand figures and the payment-ban debate together point to a structural shift in how healthcare organizations need to approach ransomware preparedness. Several implications stand out:

What the next 12 months may bring

If major English-speaking jurisdictions move to ban ransomware payments, US policymakers will face renewed pressure to follow, particularly in an environment where federal agencies have already emphasized that payments to sanctioned actors can trigger OFAC violations regardless of intent. Healthcare organizations that have deferred investment in air-gapped backups, tabletop exercises, and documented manual downtime procedures may find that the policy window for "pay and recover" closes faster than their remediation timelines allow.

The Sophos data also signals that threat actors are not retreating. A 47 percent payment rate with a rising median demand is a commercially successful model, and healthcare's structural dependency on uptime makes the sector an enduring target. Organizations that treat ransomware response planning as a once-a-year checkbox exercise rather than a continuously tested operational capability are taking on risk that neither insurance nor post-incident payment negotiations can fully offset.